Back to Blog
    No.

    Pyxos Masterclass Β· Recap

    The Data Protection Officer (DPO)

    under Saudi PDPL

    Masterclass #1114 May 2026Skanda Reddy and Richard Chudzynsky

    A recap of the Pyxos masterclass with Skanda Reddy and Richard Chudzynsky.

    A Data Protection Officer appointed in name but stripped of authority is a compliance gap, not a safeguard. That distinction animated this masterclass on the DPO role, led by Skanda Reddy and Richard Chudzynsky of Konexo (Eversheds Sutherland), whose central argument was that the role is advisory and independent rather than administrative, and that compliance depends on equipping the person, not merely designating them.

    Reddy opened on when an appointment is actually required, and was careful to separate the mandatory triggers from the wider reality. The PDPL mandates a DPO in defined circumstances tied to large-scale processing, systematic monitoring, and the processing of sensitive data, common in insurance, healthcare, and pharmacies, where sensitive personal data is pervasive. On top of that, sector regulators, the Saudi Central Bank, the Capital Markets Authority, the communications and space regulator, and the insurance regulator, layer their own requirements, and those sit alongside the baseline duties. The pair were emphatic that even where appointment is not mandated, voluntary appointment is both permitted and, in their view, advisable.

    The independence point was where the session had the most edge. The role cannot be treated as administrative, because it requires genuine command of data protection and the standing to advise the business on how to identify, manage, accept, or transfer risk, while the business, not the DPO, owns that risk. Reporting lines are where independence is won or lost: placing the DPO inside IT or security creates a built-in conflict, because those functions' objectives align with the very outcomes the DPO is meant to monitor. The more defensible home is the second line, legal, risk, or compliance, and dual-hatting the role with a position that determines the purpose and means of processing is exactly the conflict a regulator can be expected to probe.

    The session was also clear about what the role demands and what failing it costs. A DPO has to meet defined qualifications, expertise in data protection, knowledge of risk and breach handling and of the regulatory requirements, and demonstrable integrity, and must be appointed in writing, announced internally, and registered with SDAIA. Getting the function wrong is not cost-free: the PDPL's general penalty regime reaches administrative sanctions including suspension of processing, financial penalties up to five million riyals, doubled for repeat violations, and criminal liability in severe cases.

    A practical thread concerned outsourcing. The DPO can be an internal employee or an external contractor, and group arrangements are allowed, but outsourcing never transfers liability; the controller stays accountable and has to verify that an external DPO genuinely has the capacity to discharge the role.

    The session closed on a distinction worth keeping: standing up a privacy program and operating one are different phases. Building the program, the records, policies, training, and measurement, can take up to eighteen months for a large organization, after which the work becomes the ongoing operational rhythm of assessments, record updates, notice revisions, vendor reviews, and incident handling. The full qualification requirements and responsibility map are best taken from the recording and the takeaways. The DPO function, treated seriously, is a journey rather than an appointment, and the resourcing, budget, headcount, tooling, and direct access to leadership, has to match the volume and sensitivity of what the organization processes.

    About the presenters

    • Skanda Reddy

      Skanda Reddy

      Skanda Reddy is a Senior Associate at Konexo (Eversheds Sutherland), focused on PDPL and data protection implementation across Saudi Arabia and the wider region.

    • Richard Chudzynsky

      Richard Chudzynsky

      Richard Chudzynsky is a Partner at Konexo, the consulting arm of Eversheds Sutherland, leading its data practice in the Kingdom, and formerly Head of Data Protection and Privacy at PwC Middle East.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.